Re: IPSEC tunnel questions

Hi Ken,

Some time ago I was trying to resolve the same problem i.e. to keep the IPSec tunnel (no GRE) all the time up. All I found is the IPSec tunnel only come up when there is an interesting traffic coming into the tunnel. I counld't find anything that would send keep alives to keep the tunnel up.

There are few alternatives I guess, you can use GRE tunnels with IPSec in transport mode so it should keep it up all the time. The second alternative that I am using now is EZVPN server and remote in network extension mode. It all works great. With EZVPN the IPSec tunnel comes up straigth away and stays in QM_IDLE state even without intersting traffic flowing through it.

Login to the FXOS chassis manager.
Direct your browser to https://hostname/, and log-in using the user-name and password.
Go to Help > About and check the current version:
Check the current version availa...
view more

We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...
view more